SANS NewsBites is a semiweekly high-level executive summary of the most important news articles that have been published on computer security during the last week. Each news item is very briefly summarized and includes a reference on the web for detailed information, if possible.
Spend five minutes per week to keep up with the high-level perspective of all the latest security news. New issues are delivered free every Tuesday and Friday.
Volume XVIII - Issue #33
April 26, 2016
Although not "Top of the News," the two stories on Bug Bounties illuminate the value that organizations are seeing in well-managed bug bounty programs and the growing acceptance of this approach as a far more effective way to find critical vulnerabilities than relying exclusively on commercial software and/or red team services.
TOP OF THE NEWSFBI: Response Takes Precedence Over Attribution
DHS Red Teams Conduct Penetration Tests on Government Agencies
US Cyber Command Using Cyber Capabilities Against ISIS
More Bad News for NASA Cybersecurity
THE REST OF THE WEEK'S NEWSMIT Bug Bounty Program
Facebook Bug Bounty Hunter Found Evidence of Earlier Intrusion
Crop Databases Face Cyberthreats
US Military Wants Secure Messaging Platform
Two Plead Guilty in Connection with IRS "Get Transcript" Fraud
Bangladesh Bank Breach Factors
Cisco Releases Updates to Fix Denial-of-Service Flaws
DHS Wants to Improve Private Company Critical Infrastructure Data Storage
Judy Novak's PCAP Riddle Contest - Innovative Solutions Open To All
STORM CENTER TECH CORNERSTORM CENTER TECH CORNER
************************ Sponsored By Splunk ***************************
On AWS, you can't secure what you can't see. That's where Splunk can help. Splunk offers solutions that deliver end-to-end visibility on AWS. Register for our upcoming webinar to hear from a leading customer, AWS, and Splunk about how to better secure and manage your AWS environment.
- --SANS Security West | San Diego, CA | April 29-May 6 | 28 courses, bonus evening presentations, 2 nights of NetWars, multiple talks on Emerging Trends, networking opportunities and more!
- --SANS Baltimore Spring 2016 | Baltimore, MD | May 9-14 | 9 courses in IT security, cyber defense, incident handling, security management, and Windows forensics plus multiple SANS@Night talks.
- --SANS Houston 2016 | Houston, TX | May 9-14 | 7 courses including the NEW Network Penetration Testing & Ethical Hacking course.
- --SANS Stockholm 2016 | Stockholm, Sweden | May 9-14 | 5 courses. SANS training in the Nordics, 5 courses including Mobile, Virtualisation, Defending Web Apps, and Reverse Engineering Malware.
- --Security Operations Center Summit & Training | Crystal City, VA | May 19-26, 2016 | Sharing information to make cybersecurity work effectively. Two days of in-depth Summit talks, 4 SANS courses, networking, & more!
- --SANSFIRE 2016| Washington, DC | June 11-18 | Exclusive event powered by the Internet Storm Center 47 courses, bonus evening presentations, solutions expo, extraordinary networking opportunities, 2 nights of NetWars, industry receptions, and more!
- --Can't travel? SANS offers LIVE online instruction. Day (Simulcast - http://www.sans.org/u/WF) and Evening (vLive - http://www.sans.org/u/WU) courses available!
- -- Multi-week Live SANS training
Mentor - http://www.sans.org/u/X4
- --Looking for training in your own community?
Community - http://www.sans.org/u/Xj
- --SANS OnDemand lets you train anytime, anywhere with four months of online access to your course. Learn more: http://www.sans.org/u/Xy Plus Prague, Berlin, Delhi, Vienna, and Portland all in the next 90 days. For a list of all upcoming events, on-line and live:
TOP OF THE NEWS
FBI: Response Takes Precedence Over Attribution (April 21, 2016)Donald Freese, director of the FBI's National Cyber Investigative Joint Task Force, told attendees at Akamai's Government Forum last week that his team's approach to cyberattacks is to focus on response rather than attribution.
[Editor's Note (Pescatore): I like the talk - Freese is quoted as saying the FBI will work to do more blocking of attacks and less "hand-wringing." There is a definite need for more "I am certain that is an attack, so I blocked it" and less "I am certain this is an attack, so I let it continue so I could watch it do damage so I could write a report about who caused the damage." (Northcutt): That is sensible. This approach enables desist and recovery countermeasures to release as fast as possible and avoids the embarrassment of sustaining significant damage while waiting to "nail the bad guy". Take a quick look at page 38 of the CREST IR guide which builds on many guides before it and think about how to cause those actions to happen; fast:
(Honan): I hope many others follow the FBI's example. Too many people focus on the who of a breach and not on the how. ]
DHS Red Teams Conduct Penetration Tests on Government Agencies (April 25, 2016)The US Department of Homeland Security's (DHS) National Cybersecurity and Communications Integration Center (NCCIC) has conducted penetration tests on three unnamed US government civilian agencies. The red teams were able to "own those agencies from top to bottom and side-to-side." NCCIC now plans to help those agencies fix their network weaknesses. The agencies will also have help developing internal cybersecurity talent so they can continue to conduct similar assessments more frequently.
[Editor's Note (Assante): Let's pause the tactical remediation game and red team scoreboard exercise just long enough to ask ourselves why these repeated results don't necessitate a strategy change? 100% failure from incidents to red team tests should shake up the cybersecurity leadership and put a concerted effort in place to re-tool a failed strategy. (Honan): Red teaming is an effective way of identifying weaknesses in your security but do balance their findings with someone with experience in implementing secure defences. Having a pure red team person recommend defence strategies can be like having a forward in soccer be the goalkeeper for your team. Just because you excel at scoring goals, does not necessarily mean that forward will make a great goalkeeper. ]
US Cyber Command Using Cyber Capabilities Against ISIS (April 24 and 25, 2016)The New York Times reports that the US military's Cyber Command has been directed to launch cyberattacks against ISIS. These attacks are in concert with traditional weapons attacks. One reason the plan to use cyberweapons has been made public is to undermine the Islamic State's confidence in the integrity of its data and make potential recruits wary of communications.
[Editor's Note (Murray): Sounds like espionage, not sabotage. I find that comforting. We are much better at the one than the other. Dramatically lower potential for "blow-back." ]
More Bad News for NASA Cybersecurity (April 25, 2016)Two more reports have found serious cybersecurity problems at NASA. The agency's inspector general found that NASA needs to improve continuous monitoring management, configuration management, and risk management. And a private security company, Security Scorecard, ranked NASA last among 600 federal, state, and local government agencies surveyed in its report. Security Scorecard found that NASA had issues with secure sockets layer (SSL) certificates, unsecure open ports, and misconfigured email sender policy frameworks.
NASA IG Report:
[Editor's Note (Assante): I would be productive to compare the relative cyber security posture and performance of private sector space firms doing business with the US Government versus these NASA findings. These results would concern me if I was sharing sensitive and proprietary data with NASA. (Murray): These findings are not unique to NASA. Private industry may take comfort in that they are subjected to a lower level of scrutiny but should assume that the findings also apply to them. (Honan): I recommend that if you have responsibility for security in your organisation that you read this report about NASA, not to gloat over how poor their security may or may not be, but rather to look for lessons learnt to improve the security in your organisation. ]
************************** SPONSORED LINKS ********************************
1) Mark Your Calendars for April 27th Webcast: Managing Applications Securely: A SANS Survey: http://www.sans.org/info/185227
2) Cracking the Code on SaaS Security & Compliance. Thursday, April 28, 2016 at 1:00 PM EDT (17:00:00 UTC) with Brandon Cook. http://www.sans.org/info/185232
3) New Survey: Tell us how the IT community consumes AND uses cyber threat intel. Chance to win $400 Amazon Gift Card OR a FREE Summit Pass! http://www.sans.org/info/185237
THE REST OF THE WEEK'S NEWS
MIT Bug Bounty Program (April 25, 2016)The Massachusetts Institute of Technology (MIT) has launched an experimental bug bounty program. Participation is limited to MIT affiliates, including students, who have valid certifications. The program is looking for specific categories of vulnerabilities in the school's web domains. Prizes for finding flaws will be paid in TechCASH, which can be used on campus, and the top contributors will get to keep their Kerberos accounts after they graduate.
[Editor's Note (Pescatore): Well-managed bug bounty programs are showing value in a lot of use cases, with emphasis on the "well managed". The use of "TechCASH" is a unique slant - limits the pool of interested testers, but I guess reduces cost. Odds are the first target will be the TechCASH system... ]
Facebook Bug Bounty Hunter Found Evidence of Earlier Intrusion (April 22 and 25, 2016)A bug bounty hunter searching for vulnerabilities on a Facebook's internal network found evidence that a server had already been compromised. The individual found the telltale files in February, but waited until Facebook has fixed the problem to disclose details. He was awarded US $10,000 for finding the vulnerability in the server.
[Editor's Note (Williams): When conducting penetration tests, we regularly find evidence of previous or even ongoing intrusions. When negotiating a penetration test, ask your provider if they've ever seen this (if not, question why) and how it will be addressed if it happens during your penetration test. If your penetration tester gets in by exploiting a vulnerability, they may not be the first. ]
Crop Databases Face Cyberthreats (April 25, 2016)Last month, the FBI sent a Private Industry Notification to farmers, warning that data used in precision agriculture technology, or smart farming, could be targeted by data thieves. Farmers using the technology are urged to make sure that the companies that manage those data have established cybersecurity and breach response plans.
US Military Wants Secure Messaging Platform (April 25, 2016)The US military's Defense Advanced Research Projects Agency (DARPA) is seeking suppliers to develop an encrypted messaging platform based on blockchain technology. One of the goals for the new platform is to allow DoD to communicate more quickly than it does now with centralized, legacy messaging systems.
[Editor's Note (Pescatore): I think this is really more DARPA looking to do something with buzz-heavy block chain technology using small business funding methods, vs. anything serious about moving DoD to be able to communicate more quickly/securely. ]
Two Plead Guilty in Connection with IRS "Get Transcript" Fraud (April 22 and 25, 2016)Two people have pleaded guilty to charges of conspiracy to commit money laundering and illegally structuring cash withdrawals to evade bank reporting requirements for their roles in a scheme to defraud the US Internal Revenue Service (IRS). The scheme involved exploited the "Get Transcript" tool to obtain taxpayers' personal information and filing fraudulent returns to obtain refunds. Another person involved in the scheme pleaded guilty to money laundering earlier this year.
DoJ Press Release:
Bangladesh Bank Breach Factors (April 22 and 25, 2016)According to Reuters, some of the contributing factors in the US $80 million theft from the Bangladesh central bank included the use of inexpensive, second-hand routers and the lack of a firewall. In addition, an investigation conducted by BAE Systems suggests the attackers tricked the SWIFT financial software with custom malware.
[Editor's Note (Liston): For those of us who cut our reverse-engineering teeth on these kinds of things, the malware bypassed an integrity check by creating an in-memory patch of liboradb.dll - overwriting a JNZ check with NOPs. +ORC would be proud:
Cisco Releases Updates to Fix Denial-of-Service Flaws (April 21 and 22, 2016)Cisco has published five security alerts regarding vulnerabilities in three products that could be exploited to create denial-of-service conditions. The flaws affect Cisco Wireless LAN Controller (WLC) software, Cisco Adaptive Security Appliance (ASA) software, and the Secure Real-Time Transport Protocol (SRTP) library.
[Editor's Note (Williams): Although these vulnerabilities are mostly rated as DoS, remember that a vendor rated DoS can quickly become a remote code execution (RCE) when the right creative mind gets ahold of it. We saw this last year with MS15-034. It was originally classified as only DoS but was updated to include RCE after exploit code was sold in exploit markets. Patch your systems now to reduce exposure. ]
DHS Wants to Improve Private Company Critical Infrastructure Data Storage (April 20, 2016)The Department of Homeland Security wants to revamp an outdated system for holding sensitive data from private companies that operate elements of the country's critical infrastructure. The Protected Critical Infrastructure Information Program (PCII) stores security reviews, submitted as paper reports. DHS wants to move "to state-of-the-art technology that operates within a digital environment."
Judy Novak's PCAP Riddle Contest - Innovative Solutions Open To All Readers (April 26, 2016)Five days ago the SANS Institute sent an email to 101k security professionals as a Save the Date for an upcoming conference and to announce a security contest designed by Judy Novak. By April 25 there were four winners, all members of the GIAC Advisory Board. Their solutions are very innovative, each approached the problem differently:
The PCAP, (network packet storage) file is available on this web page if you want to try some of their techniques:
STORM CENTER TECH CORNERAngler EK Used to Spread CryptXXX
Honeyports Powershell Script
Online Credit Card Fraud Soars
How to Trick Traffic Sensors
Opera VPN Service Analysis
Apple Image IO Denial of Service
Text Messages Used to Phish Apple IDs
Critical HP Data Protector Patch
Armada Collection (or imposter) Making Fake DDoS Threats
The Editorial Board of SANS NewsBites
John Pescatore was Vice President at Gartner Inc. for fourteen years. He became a director of the SANS Institute in 2013. He has worked in computer and network security since 1978 including time at the NSA and the U.S. Secret Service.
Shawn Henry is president of CrowdStrike Services. He retired as FBI Executive Assistant Director responsible for all criminal and cyber programs and investigations worldwide, as well as international operations and the FBI's critical incident response.
Suzanne Vautrinot was Commander of the 24th Air Force (AF Cyber) and now sits on the board of directors of Wells Fargo and several other major organizations.
Ed Skoudis is co-founder of CounterHack, the nation's top producer of cyber ranges, simulations, and competitive challenges, now used from high schools to the Air Force. He is also author and lead instructor of the SANS Hacker Exploits and Incident Handling course, and Penetration Testing course.
Michael Assante was Vice President and Chief Security Officer at NERC, led a key control systems group at Idaho National Labs, and was American Electric Power's CSO. He now leads the global cyber skills development program at SANS for power, oil & gas and other critical infrastructure industries.
Mark Weatherford is Chief Cybersecurity Strategist at vArmour and the former Deputy Under Secretary of Cybersecurity at the US Department of Homeland Security.
Stephen Northcutt teaches advanced courses in cyber security management; he founded the GIAC certification and was the founding President of STI, the premier skills-based cyber security graduate school, www.sans.edu.
Dr. Johannes Ullrich is Chief Technology Officer of the Internet Storm Center and Dean of the Faculty of the graduate school at the SANS Technology Institute.
William Hugh Murray is an executive consultant and trainer in Information Assurance and Associate Professor at the Naval Postgraduate School.
Sean McBride is Director of Analysis and co-founder of Critical Intelligence, and, while at Idaho National Laboratory, he initiated the situational awareness effort that became the ICS-CERT.
Rob Lee is the SANS Institute's top forensics instructor and director of the digital forensics and incident response research and education program at SANS (computer-forensics.sans.org).
Tom Liston is member of the Cyber Network Defense team at UAE-based Dark Matter. He is a Handler for the SANS Institute's Internet Storm Center and co-author of the book Counter Hack Reloaded.
Jake Williams is a SANS course author and the founder of Rendition Infosec, with experience securing DoD, healthcare, and ICS environments.
Dr. Eric Cole is an instructor, author and fellow with The SANS Institute. He has written five books, including Insider Threat and he is a founder with Secure Anchor Consulting.
Mason Brown is one of a very small number of people in the information security field who have held a top management position in a Fortune 50 company (Alcoa). He leads SANS' efforts to raise the bar in cybersecurity education around the world.
David Hoelzer is the director of research & principal examiner for Enclave Forensics and a senior fellow with the SANS Technology Institute.
Gal Shpantzer is a trusted advisor to CSOs of large corporations, technology startups, Ivy League universities and non-profits specializing in critical infrastructure protection. Gal created the Security Outliers project in 2009, focusing on the role of culture in risk management outcomes and contributes to the Infosec Burnout project.
Eric Cornelius is Director of Critical Infrastructure and ICS at Cylance, and earlier served as deputy director and chief technical analyst for the Control Systems Security Program at the US Department of Homeland Security.
Alan Paller is director of research at the SANS Institute.
Brian Honan is an independent security consultant based in Dublin, Ireland.
David Turley is SANS operations manager and serves as production manager and final editor on SANS NewsBites.
Please feel free to share this with interested parties via email, but no posting is allowed on web sites. For a free subscription, (and for free posters) or to update a current subscription, visit http://portal.sans.org/